<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Security News Blog</title>
	<atom:link href="http://securitynewsblog.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://securitynewsblog.wordpress.com</link>
	<description>Up to date Info Sec news - Sponsored by PotentiaHosting.com</description>
	<lastBuildDate>Fri, 18 Dec 2009 14:44:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='securitynewsblog.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Security News Blog</title>
		<link>http://securitynewsblog.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://securitynewsblog.wordpress.com/osd.xml" title="Security News Blog" />
	<atom:link rel='hub' href='http://securitynewsblog.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Twitter Hacked &#8211; DNS hijacked</title>
		<link>http://securitynewsblog.wordpress.com/2009/12/18/twitter-hacked-dns-hijacked/</link>
		<comments>http://securitynewsblog.wordpress.com/2009/12/18/twitter-hacked-dns-hijacked/#comments</comments>
		<pubDate>Fri, 18 Dec 2009 14:38:15 +0000</pubDate>
		<dc:creator>securitynewblog</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://securitynewsblog.wordpress.com/?p=24</guid>
		<description><![CDATA[Twitter Hacked &#8211; could it happen to you? Today’s posting sponsored by: On 12/17/2008 around 7:00 PM EST , Twitter.com was hacked by a group claiming to be the Iranian Cyber Army. The actual attack was a DNS Hijacking (or DNS Poisoning) that resulted in Twitter Users being directed to a page of their choosing. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securitynewsblog.wordpress.com&amp;blog=10938708&amp;post=24&amp;subd=securitynewsblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<blockquote><p>Twitter Hacked &#8211; could it happen to you?</p></blockquote>
<h3>Today’s posting sponsored by:</h3>
<p><a href="http://www.potentiahosting.com"><img class="aligncenter size-medium wp-image-9" title="PotentiaHosting - Unleash your site's potential!" src="http://securitynewsblog.files.wordpress.com/2009/12/potentialogo_banner1.png?w=300&#038;h=33" alt="" width="300" height="33" /></a></p>
<h3><a href="http://securitynewsblog.files.wordpress.com/2009/12/potentialogo_banner1.png"></a></h3>
<p>On 12/17/2008 around 7:00 PM EST , Twitter.com was hacked by a group claiming to be the Iranian Cyber Army. The actual attack was a DNS Hijacking (or DNS Poisoning) that resulted in Twitter Users being directed to a page of their choosing. In this example here is what they posted:</p>
<p>This old school defacement actually was conducted by &#8216;hijacking&#8217; the sites DNS &#8211; how they accomplished this is still unknown, the fact is they did. What exactly is a DNS Poisioning or Hijacking?</p>
<p>Quite simply, when your desktop or any other Internet enabled device wants to talk to another compute or device, you would typically put in the domain name, www.domain.com for instance. If you had &#8216;recently&#8217; visited this site, then the cache (arp cache) on your machine or server would likely have its IP address. If not then it will ask it&#8217;s DNS or Domain Name Server for help. The DNS server will follow the trail to find the target, domain.com&#8217;s DNS server &#8211; theoretically it will return to you the IP address of domain.com.</p>
<p>In Twitter&#8217;s case, the iRANiAN.CYBER.ARMY@&#8230; penetrated twitter and replaced their DNS Servers with a choosing of their own. This is done many times in Phishing scams to redirect you to a &#8216;fake&#8217; but very real looking page. The unsuspecting person browsing would carry on their work (say banking) all the while they are giving the bad guys their real details. A super clever hacker would quietly record this &#8211; then log you into the bank &#8211; you would never know. They have your passwords,  you are happy. A bad situation.</p>
<p>What is interesting is that it appears that the only redirect was to this stupid page, &#8212; complete with their email address (attention google are you looking?) , they could have directed the twittersphere to a malware site (this may have been one), or put up a fake Twitter Login page &#8211; to scam user/passwords or more.</p>
<p>That brings me to this &#8211; Have you tested the integrity of your DNS on your servers?  Cricket Liu &#8211; a recogonized authority on DNS has a set of tools and services available to help you check your site -  you can give your DNS infrastructure a good look &#8211; and if you think that you aren&#8217;t vulnerable &#8211; Twitter was &#8211; maybe you should look again.</p>
<p><a title="infoblox.com" href="http://www.infoblox.com/services/dns-advisor-pro.cfm?gclid=CLXUt7aQ4J4CFRafnAodaQPAJQ" target="_blank">You can reach Cricket Liu&#8217;s site here.</a> And here is a <a title="dns.net whitepaper" href="http://www.dns.net/dnsrd/docs/domain.pdf" target="_blank">short white paper</a> on DNS to help you have a better understanding on how DNS works.</p>
<p><em>Tom is a security expert, and he has authored the book <a href="http://www.amazon.com/Joomla-Web-Security-Tom-Canavan/dp/1847194885/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1257459620&amp;sr=8-1" target="_blank">Joomla Web Security</a> (Packt) as well as <a href="http://www.amazon.com/Dodging-Bullets-Disaster-Preparation-Joomla/dp/059543956X/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1257459835&amp;sr=1-1" target="_blank">Dodging the Bullets &#8211; A Disaster Preparation Guide for Joomla! Based Websites</a>. He offers his services to Joomla and WordPress websites that have been attacked and compromised at <a title="JoomlaRescue.com - Dedicated to securing YOUR server" href="http://www.joomlarescue.com/">JoomlaRescue.com</a>.<br />
</em></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securitynewsblog.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securitynewsblog.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securitynewsblog.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securitynewsblog.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securitynewsblog.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securitynewsblog.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securitynewsblog.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securitynewsblog.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securitynewsblog.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securitynewsblog.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securitynewsblog.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securitynewsblog.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securitynewsblog.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securitynewsblog.wordpress.com/24/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securitynewsblog.wordpress.com&amp;blog=10938708&amp;post=24&amp;subd=securitynewsblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securitynewsblog.wordpress.com/2009/12/18/twitter-hacked-dns-hijacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/11be48539c73db71f2982ff9e8b6ca52?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Security News Blog</media:title>
		</media:content>

		<media:content url="http://securitynewsblog.files.wordpress.com/2009/12/potentialogo_banner1.png?w=300" medium="image">
			<media:title type="html">PotentiaHosting - Unleash your site&#039;s potential!</media:title>
		</media:content>
	</item>
		<item>
		<title>Information Security News &#8211; Dec 13, 2009</title>
		<link>http://securitynewsblog.wordpress.com/2009/12/13/information-security-news-dec-13-2009/</link>
		<comments>http://securitynewsblog.wordpress.com/2009/12/13/information-security-news-dec-13-2009/#comments</comments>
		<pubDate>Sun, 13 Dec 2009 18:11:29 +0000</pubDate>
		<dc:creator>securitynewblog</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://securitynewsblog.wordpress.com/?p=4</guid>
		<description><![CDATA[Today&#8217;s posting sponsored by: MessageLabs &#8217;09 Report: Botnets Bounce Back With Sharpened Survival Skills December 11, 2009 The bad guys sharpened their skills, rather than just relying on large spam runs and malware attacks Some 132K Websites Hit By New SQL Injection Attack December 10, 2009 ScanSafe reports widespread attack that continues to grow New [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securitynewsblog.wordpress.com&amp;blog=10938708&amp;post=4&amp;subd=securitynewsblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h3>Today&#8217;s posting sponsored by:</h3>
<h1><a href="http://www.potentiahosting.com" target="_blank"><img class="alignleft size-medium wp-image-9" title="PotentiaHosting - Unleash your site's potential!" src="http://securitynewsblog.files.wordpress.com/2009/12/potentialogo_banner1.png?w=300&#038;h=33" alt="" width="300" height="33" /></a></h1>
<p><a href="http://www.potentiahosting.com" target="_blank"></a></p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=222001767&amp;subSection=Attacks/breaches">MessageLabs &#8217;09 Report: Botnets Bounce Back With Sharpened Survival Skills </a></h3>
<p>December 11, 2009<br />
The bad guys sharpened their skills, rather than just relying on large spam runs and malware attacks</p>
<h3><a href="http://www.darkreading.com/vulnerability_management/security/attacks/showArticle.jhtml?articleID=222001558&amp;subSection=Attacks/breaches"> Some 132K Websites Hit By New SQL Injection Attack </a></h3>
<p>December 10, 2009<br />
ScanSafe reports widespread attack that continues to grow</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=222001216&amp;subSection=Attacks/breaches"> New Verizon Business Report Outlines 15 Most Common Attacks </a></h3>
<p>December 9, 2009<br />
Keylogging and spyware are among the most commonly found exploits in breached companies, report says</p>
<h2 class="mceIEcenter">
<dl class="aligncenter">
<dt><a href="http://www.amazon.com/Joomla-Web-Security-Tom-Canavan/dp/1847194885/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1257534620&amp;sr=8-1"><img title="Joomla! Web Security - Book - available from Amazon.com" src="http://securitynewsblog.files.wordpress.com/2009/12/book-post.png?w=194&#038;h=300" alt="Joomla! Web Security - Book - available from Amazon.com" width="194" height="300" /></a></dt>
<dd><strong><a href="http://www.amazon.com/Joomla-Web-Security-Tom-Canavan/dp/1847194885/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1257534620&amp;sr=8-1" target="_blank">Need Security? Get the book &#8211; Joomla! Web Security</a></strong></dd>
</dl>
</h2>
<h3><a href="http://www.darkreading.com/vulnerability_management/security/attacks/showArticle.jhtml?articleID=222000147&amp;subSection=Attacks/breaches"> Metasploit Gets New Vulnerabilty Scanning Features </a></h3>
<p>December 1, 2009<br />
Rapid7 takes first step in integrating penetration testing tool with its NeXpose vulnerability scanner, rolls out new free version of NeXpose</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=222000115&amp;subSection=Attacks/breaches"> Hacker Arrested For Stealing Virtual Assets In Online Game </a></h3>
<p>December 1, 2009<br />
Man allegedly broke into almost 300 RuneScape accounts, police say</p>
<h3><a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=221901428&amp;subSection=Attacks/breaches"> Heap Spraying: Attackers&#8217; Latest Weapon Of Choice </a></h3>
<p>November 30, 2009<br />
Difficult to detect reliably, heap spraying was behind an exploit of IE and Adobe Reader</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=221901397&amp;subSection=Attacks/breaches"> Perimeter E-Security: Top Ten Biggest Security Breaches And Blunders of 2009 </a></h3>
<p>November 30, 2009<br />
A common thread between all of these incidents: They could have been avoided</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=221901213&amp;subSection=Attacks/breaches"> New Exploit Masquerades As Flash Player Upgrade </a></h3>
<p>November 25, 2009<br />
Phishing campaign has hit more than 3.5 million mailboxes, researchers say</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=221900520&amp;subSection=Attacks/breaches"> Three Indicted For Comcast Site Hack </a></h3>
<p>November 20, 2009<br />
&#8216;Kryogeniks&#8217; gang redirected traffic to its own Web page in 2008</p>
<h3><a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=221900096&amp;subSection=Attacks/breaches"> FBI Warns Of Spear Phishing Attacks On U.S. Law Firms and Public Relations Firms </a></h3>
<p>November 18, 2009<br />
Socially engineered e-mail designed to compromise a network by bypassing technological network defenses and exploiting the person at the keyboard</p>
<h3><a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=221800360&amp;subSection=Attacks/breaches"> Big-Name Vendors Team On Disaster Preparedness, Recovery </a></h3>
<p>November 17, 2009<br />
IT can play a major role in boosting the effectiveness of response efforts, say alliance sponsors that include Microsoft, Google, Yahoo</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=221800213&amp;subSection=Attacks/breaches"> D.A. Davidson Breach Case Nears Resolution </a></h3>
<p>November 16, 2009<br />
Judge approves settlement of lawsuit; three Latvian suspects extradited</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=221800146&amp;subSection=Attacks/breaches"> Conn. AG Investigates Blue Cross Blue Shield Data Breach </a></h3>
<p>November 16, 2009<br />
BC/BS and its related companies Anthem and Empire failed to inform health care providers until late last month, says Connecticut Attorney General Richard Blumenthal</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=221601340&amp;subSection=Attacks/breaches"> iPhone Targeted Yet Again </a></h3>
<p>November 11, 2009<br />
New hacking tool steals personal data off &#8216;jailbroken&#8217; iPhones via a wireless network</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=221601198&amp;subSection=Attacks/breaches"> Alleged $9 Million Hacking Ring Exposed </a></h3>
<p>November 11, 2009<br />
Group broke into credit card systems at RBS Worldpay, DoJ says</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=221600945&amp;subSection=Attacks/breaches"> MassMutual Warns Of Data Breach </a></h3>
<p>November 10, 2009<br />
Database may have been compromised via third party vendor</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=221600879&amp;subSection=Attacks/breaches"> Product Watch: Verizon Launches Data Discovery, Identification, And Security Classification Service </a></h3>
<p>November 9, 2009<br />
New service reflects shift to &#8216;data-centric&#8217; view of security, Verizon says</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=221600700&amp;subSection=Attacks/breaches"> Gumblar Botnet Resurges </a></h3>
<p>November 6, 2009<br />
Reactivation of Gumblar.cn domain could have ripple effect, researchers say</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=221600421&amp;subSection=Attacks/breaches"> Spain And United States Top Global Ranking Of Bot-Infected Computers </a></h3>
<p>November 5, 2009<br />
Countries least infected include Peru, the Netherlands, and Sweden</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=221600184&amp;subSection=Attacks/breaches"> DDoS-As-A-Service Open For Business </a></h3>
<p>November 3, 2009<br />
McAfee report says botnet operators are increasingly contracting out their botnets to distributed denial-of-service attack service providers</p>
<h3><a href="http://www.darkreading.com/vulnerability_management/security/attacks/showArticle.jhtml?articleID=221600127&amp;subSection=Attacks/breaches"> Researchers Create Hypervisor-Based Tool For Blocking Rootkits </a></h3>
<p>November 3, 2009<br />
New technology &#8216;patches&#8217; the operating system kernel, protects it from rootkits</p>
<h3><a href="http://www.darkreading.com/insiderthreat/security/attacks/showArticle.jhtml?articleID=221600109&amp;subSection=Attacks/breaches"> FBI: Fraudulent Automated Clearing House (ACH) Transfers Connected to Malware and Work-at-Home Scams </a></h3>
<p>November 3, 2009<br />
FBI says there&#8217;s been a significant increase in fraud involving the exploitation of valid online banking credentials belonging to small and medium businesses, municipal governments, and school districts</p>
<h3><a href="http://www.darkreading.com/vulnerability_management/security/attacks/showArticle.jhtml?articleID=221500012&amp;subSection=Attacks/breaches"> Microsoft Report: Worms Rise, New Vulnerabilities Decline </a></h3>
<p>November 2, 2009<br />
The new Microsoft Security Intelligence Report (SIR) found worm infections nearly doubled, vulnerability counts down by nearly one-third in the first half of 2009</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=221100157&amp;subSection=Attacks/breaches"> Facebook Phishing Attack Powered By Zeus Botnet, Researchers Say </a></h3>
<p>October 28, 2009<br />
Scam email messages being generated at a rate of 1,000 per minute</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=220900781&amp;subSection=Attacks/breaches"> Trusteer Discovers Two-Headed Trojan Attack On Banks </a></h3>
<p>October 28, 2009<br />
W32.Silon bypasses security tokens, banking card readers and uses a two-pronged payload to steal login information and commit online financial fraud</p>
<h3><a href="http://www.darkreading.com/insiderthreat/security/attacks/showArticle.jhtml?articleID=220601211&amp;subSection=Attacks/breaches"> Ex-Ford Engineer Indicted For Allegedly Stealing Company Secrets </a></h3>
<p>October 16, 2009<br />
Xiang Dong Yu allegedly copied 4,000 sensitive Ford documents onto a USB drive before leaving the company</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=220600886&amp;subSection=Attacks/breaches"> DIY: Defending Against A DDoS Attack </a></h3>
<p>October 14, 2009<br />
Proactive self-defense can make DDoS attacks less painful and damaging</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=220301690&amp;subSection=Attacks/breaches"> &#8216;Operation Phish Phry&#8217; Nets 100 Suspects In Major Bank-Fraud Ring </a></h3>
<p>October 8, 2009<br />
Bust represents largest number of defendants ever charged in a U.S. cybercrime case, FBI says</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=220301086&amp;subSection=Attacks/breaches"> Breach At Pharmaceutical Benefits Company May Have Affected 700,000 </a></h3>
<p>October 5, 2009<br />
FBI investigation of 2008 incident leads Express Scripts to notify hundreds of thousands about potential breach</p>
<h3><a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=220301057&amp;subSection=Attacks/breaches"> Report: Most Companies Unprepared For Quick Response To Attack </a></h3>
<p>October 5, 2009<br />
Most companies do not have the capability to determine the full scope of security incidents</p>
<h3><a href="http://www.darkreading.com/database_security/security/attacks/showArticle.jhtml?articleID=220100950&amp;subSection=Attacks/breaches"> Couple&#8217;s Lawsuit Against Bank Over Breach To Move Forward </a></h3>
<p>September 23, 2009<br />
Case raises questions about banks&#8217; liability in breach of customers&#8217; online accounts</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=220100919&amp;subSection=Attacks/breaches"> PCI More Of A &#8216;Check-Box&#8217; Than Security For Most Retailers </a></h3>
<p>September 23, 2009<br />
New survey shows less than one-third of small businesses are PCI-compliant, while 70 of large businesses are</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=220100567&amp;subSection=Attacks/breaches"> Cyveillance Disputes Reports Of Phishing Decline </a></h3>
<p>September 22, 2009<br />
Cyveillance detects 176,864 distinct phishing attacks between June and August 2009, one of the highest three-month totals on record</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=220000940&amp;subSection=Attacks/breaches"> New Free Web Service Confirms Theft Of Your Identity </a></h3>
<p>September 17, 2009<br />
Web-based search service lets individuals check &#8212; in detail &#8212; whether their personal information has been compromised</p>
<h3><a href="http://www.darkreading.com/securityservices/security/attacks/showArticle.jhtml?articleID=219700075&amp;subSection=Attacks/breaches"> New Twitter Security Experiment Goes Live </a></h3>
<p>September 8, 2009<br />
Errata Security&#8217;s TwiGUARD service detects Twitter spam, malicious links</p>
<h3><a href="http://www.darkreading.com/insiderthreat/security/attacks/showArticle.jhtml?articleID=219500666&amp;subSection=Attacks/breaches"> &#8216;Freakshow&#8217; Provides Inside Look At Real Malware Behind Big Breaches </a></h3>
<p>August 31, 2009<br />
Forensic specialists who investigated hacks of a hotel chain, casino, and restaurant share details on the sophisticated malware used to successfully steal confidential data</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=219500613&amp;subSection=Attacks/breaches"> Zeus Trojan Uses IM Speed Distribution Of Stolen Data </a></h3>
<p>August 31, 2009<br />
Jabber IM module built into Trojan sends compromised data quickly to mobile criminals</p>
<h3><a href="http://www.darkreading.com/insiderthreat/security/attacks/showArticle.jhtml?articleID=219500368&amp;subSection=Attacks/breaches"> Attack Of The Tweets: Major Twitter Flaw Exposed </a></h3>
<p>August 27, 2009<br />
U.K. researcher says vulnerability in Twitter API lets an attacker take over a victim&#8217;s account &#8212; with a tweet</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=219400520&amp;subSection=Attacks/breaches"> Social Networks Number One Web Attack Target </a></h3>
<p>August 18, 2009<br />
Web Hacking Incidents Database (WHID) report finds that one-fifth of Web incidents were aimed at Web 2.0 sites in the first half of 2009</p>
<h3><a href="http://www.darkreading.com/database_security/security/attacks/showArticle.jhtml?articleID=219400495&amp;subSection=Attacks/breaches"> Mega-Breaches Employed Familiar, Preventable Attacks </a></h3>
<p>August 18, 2009<br />
Alleged mastermind behind Heartland, Hannaford&#8217;s, and 7-11 breaches used SQL injection, sniffers, custom malware in attacks</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=219100434&amp;subSection=Attacks/breaches"> Ukrainian Attackers Use SEO, Fed Forms To Push Scareware To U.S. Users </a></h3>
<p>August 7, 2009<br />
Hackers &#8220;hijack&#8221; keywords to U.S. federal forms, placing malware at top of search results</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=219100293&amp;subSection=Attacks/breaches"> Twitter Under DDoS Attack </a></h3>
<p>August 6, 2009<br />
Tweets go silent as microblogging social network site gets downed by a distributed denial-of-service attack; Facebook and LiveJournal also reportedly hit</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=219100135&amp;subSection=Attacks/breaches"> Weaponizing Apple&#8217;s iPod Touch </a></h3>
<p>August 5, 2009<br />
Security expert converts popular music/movie player and browsing device into a penetration testing, hacking tool</p>
<h3><a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=219000208&amp;subSection=Attacks/breaches"> Netronome Unveils SSL Inspector Appliance </a></h3>
<p>August 4, 2009<br />
Solution prevents man-in-the-middle attacks by detecting SSL traffic, validating SSL certificates, and stopping connection, if warranted</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=218900552&amp;subSection=Attacks/breaches"> Hackers Rig ATMs In Las Vegas Hotel, Secret Service Investigating </a></h3>
<p>August 3, 2009<br />
While white-hat hackers were trying to stay one step ahead of the bad guys at Black Hat USA and Defcon, a real computer crime was committed nearby</p>
<h3><a href="http://www.darkreading.com/database_security/security/intrusion-prevention/showArticle.jhtml?articleID=218600829&amp;subSection=Attacks/breaches"> Astaro Offers SMBs Free Silent Business Audit And Forensic Analysis </a></h3>
<p>July 27, 2009<br />
Offer will demonstrate what spyware and malware is able to get by the organization&#8217;s spam filter, and will provide insight into Internet usage trends</p>
<h3><a href="http://www.darkreading.com/security/showArticle.jhtml?articleID=218600221&amp;subSection=Attacks/breaches"> FishNet Security Accredited By Visa As Qualified Incident Response Assessor </a></h3>
<p>July 22, 2009<br />
Company can perform forensic investigations and oversee remediation efforts following a payment card data compromise</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=218501021&amp;subSection=Attacks/breaches"> Hacker Stole Internal Twitter Documents In Targeted Attack On Employee </a></h3>
<p>July 16, 2009<br />
Twitter co-founder blames weak passwords, likens incident to &#8216;underwear drawer&#8217; being rifled through, while experts question internal security controls</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=218401542&amp;subSection=Attacks/breaches"> Twitter Suspends User Accounts Infected With Koobface Worm </a></h3>
<p>July 10, 2009<br />
Researchers say worm sends tweets with a variety of URLs that lead victims to malware infection</p>
<h3><a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=218400843&amp;subSection=Attacks/breaches"> Bug Now Being Exploited In Microsoft Zero-Day Attacks Was Reported A Year Ago </a></h3>
<p>July 7, 2009<br />
Researchers in 2008 disclosed Windows video control vulnerability that&#8217;s now spreading attacks to some .com, .org Websites</p>
<p style="text-align:left;">
<p style="text-align:left;">
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/securitynewsblog.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/securitynewsblog.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/securitynewsblog.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/securitynewsblog.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/securitynewsblog.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/securitynewsblog.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/securitynewsblog.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/securitynewsblog.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/securitynewsblog.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/securitynewsblog.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/securitynewsblog.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/securitynewsblog.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/securitynewsblog.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/securitynewsblog.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=securitynewsblog.wordpress.com&amp;blog=10938708&amp;post=4&amp;subd=securitynewsblog&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://securitynewsblog.wordpress.com/2009/12/13/information-security-news-dec-13-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/11be48539c73db71f2982ff9e8b6ca52?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Security News Blog</media:title>
		</media:content>

		<media:content url="http://securitynewsblog.files.wordpress.com/2009/12/potentialogo_banner1.png?w=300" medium="image">
			<media:title type="html">PotentiaHosting - Unleash your site&#039;s potential!</media:title>
		</media:content>

		<media:content url="http://securitynewsblog.files.wordpress.com/2009/12/book-post.png?w=194" medium="image">
			<media:title type="html">Joomla! Web Security - Book - available from Amazon.com</media:title>
		</media:content>
	</item>
	</channel>
</rss>
